« Volver al listado

CVE-2026-34780

Estado: ModificadaMedia (6.1)—

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the contextBridge are vulnerable to a context isolation bypass. An attacker who can execute JavaScript in the main world (for example, via XSS) can use a bridged VideoFrame to gain access to the isolated world, including any Node.js APIs exposed to the preload script.

Leer descripción completaMostrar menos

Apps are only affected if a preload script returns, resolves, or passes a VideoFrame object to the main world via contextBridge.exposeInMainWorld(). Apps that do not bridge VideoFrame objects are not affected. This issue has been patched in versions 39.8.0, 40.7.0, and 41.0.0-beta.8.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-34780",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-34780",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-07T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.3
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "electron",
          "product": "electron",
          "versions": [
            {
              "status": "affected",
              "version": ">= 39.0.0-alpha.1, < 39.8.0"
            },
            {
              "status": "affected",
              "version": ">= 40.0.0-alpha.1, < 40.7.0"
            },
            {
              "status": "affected",
              "version": ">= 41.0.0-alpha.1, < 41.0.0-beta.8"
            }
          ]
        }
      ]
    },
    {
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
      "affectedData": [
        {
          "cpes": [
            "cpe:/a:redhat:podman_desktop:1"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Build of Podman Desktop",
          "packageName": "podman-desktop-macos-1-0",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:podman_desktop:1"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Build of Podman Desktop",
          "packageName": "podman-desktop-windows-1-0",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:podman_desktop:0"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Build of Podman Desktop - Tech Preview",
          "packageName": "rhdesktop/rh-podman-desktop-ext-openshift-local-rhel10",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-04-04T01:16:39.540",
  "references": [
    {
      "url": "https://github.com/electron/electron/security/advisories/GHSA-jfqg-hf23-qpw2",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-34780",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455020",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34780.json",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-668"
        },
        {
          "lang": "en",
          "value": "CWE-1188"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
      "description": [
        {
          "lang": "en",
          "value": "CWE-501"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the contextBridge are vulnerable to a context isolation bypass. An attacker who can execute JavaScript in the main world (for example, via XSS) can use a bridged VideoFrame to gain access to the isolated world, including any Node.js APIs exposed to the preload script. Apps are only affected if a preload script returns, resolves, or passes a VideoFrame object to the main world via contextBridge.exposeInMainWorld(). Apps that do not bridge VideoFrame objects are not affected. This issue has been patched in versions 39.8.0, 40.7.0, and 41.0.0-beta.8."
    },
    {
      "lang": "es",
      "value": "Electron es un framework para escribir aplicaciones de escritorio multiplataforma usando JavaScript, HTML y CSS. Desde las versiones 39.0.0-alpha.1 hasta antes de la 39.8.0, 40.0.0-alpha.1 hasta antes de la 40.7.0, y 41.0.0-alpha.1 hasta antes de la 41.0.0-beta.8, las aplicaciones que pasan objetos VideoFrame (de la API WebCodecs) a través del contextBridge son vulnerables a una omisión del aislamiento de contexto. Un atacante que puede ejecutar JavaScript en el mundo principal (por ejemplo, a través de XSS) puede usar un VideoFrame puenteado para obtener acceso al mundo aislado, incluyendo cualquier API de Node.js expuesta al script de precarga. Las aplicaciones solo se ven afectadas si un script de precarga devuelve, resuelve o pasa un objeto VideoFrame al mundo principal a través de contextBridge.exposeInMainWorld(). Las aplicaciones que no puentean objetos VideoFrame no se ven afectadas. Este problema ha sido parcheado en las versiones 39.8.0, 40.7.0 y 41.0.0-beta.8."
    }
  ],
  "lastModified": "2026-07-24T22:10:00.140",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "642CA6B2-000A-480D-B062-80593D150787",
              "versionEndExcluding": "39.8.0",
              "versionStartIncluding": "39.0.0"
            },
            {
              "criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E54036E0-1D1F-4265-A2F3-B9C1F88F65ED",
              "versionEndExcluding": "40.7.0",
              "versionStartIncluding": "40.0.0"
            },
            {
              "criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha1:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A20225D6-F435-4D09-962D-B162F521B6AD"
            },
            {
              "criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha2:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33712802-EB60-4E9A-83B8-9F2320B70CB4"
            },
            {
              "criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha3:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D0A9142-54FE-47BB-9FEB-5E97528E28FE"
            },
            {
              "criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha4:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E1D191F-DEAE-4DB3-9822-F31AF9FE3BAC"
            },
            {
              "criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha5:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "45A8192F-3D2C-4987-9BBE-7ECC3F71965D"
            },
            {
              "criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha6:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EEA1A2E5-03DB-46CB-8427-7F31A8A7CE1C"
            },
            {
              "criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta1:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2DFCE75-BD3F-4537-B5B8-14097E262EA2"
            },
            {
              "criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta2:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC346E25-EA43-4615-8CDB-16D15D46E4FF"
            },
            {
              "criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta3:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA5B3C00-CAFC-4995-BF35-9920F3039E77"
            },
            {
              "criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta4:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3672F3FB-6B5E-40FD-8A92-CB4DD6BC6A93"
            },
            {
              "criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta5:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9EE4F8AE-21D2-4815-85B7-B7ECCC0D5059"
            },
            {
              "criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta6:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D195760C-7DD9-4259-9042-EDE65AEAC1D6"
            },
            {
              "criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta7:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B370859F-24D3-4B25-B580-1A5B6DB94BFE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}